WCU / Cybersecurity
Home
CSC 471
CSC 472
Search
/
~
/
CSC 472
/
Class 03
CSC 472 · Class 03
Buffer Overflows and Return-Address Hijacking
17 knowledge points. Work through them in order, or jump to any topic.
//
Knowledge Points
01
Goal of Today
→
02
Ground Rules
→
03
What Is a Buffer Overflow?
→
04
The Usual Suspects (Unbounded Copies)
→
05
Stack Layout: buf, saved RBP, return address
→
06
Before vs. After the Overflow
→
07
Hijacking Control Flow
→
08
ret2win: Redirect to an Existing Function
→
09
The Payload = Padding + Target Address
→
10
Finding the Offset with Cyclic Patterns
→
11
Finding the Offset by Inspecting the Crash
→
12
32-bit vs. 64-bit Differences
→
13
The movaps Stack-Alignment Caveat (64-bit)
→
14
Vulnerable Functions Cheat-Sheet
→
15
Defenses Preview (full treatment in Class 05)
→
16
Tie-In to Lab 2
→
17
Summary
→